Description
A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-04
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists in an unknown function of the "/customer/" endpoint within the CoinEx Crypto Customer Profile API. By manipulating the "ID" argument, an attacker can bypass authorization checks and obtain access to another user’s customer profile. The description indicates that the attack can be launched remotely and that the exploit has been publicly disclosed, implying that attackers could mount this attack without needing to gain initial foothold on the system. The CVSS score of 5.3 reflects medium severity, suggesting that while the exploit does not provide remote code execution, it still permits unauthorized access to sensitive customer data. The lack of an EPSS value and absence from the CISA KEV catalog means that publicly available data does not indicate an imminent or widespread exploitation trend, but the remote nature of the attack and public disclosure warrant prompt attention.

Affected Systems

Affected systems are Omega Solution’s CoinEx Crypto platform, version 2025, as indicated by the vendor name and product S/W id. The specific function impacted resides in the file located at "/customer/" within the Customer Profile API component. There is no explicit version range beyond the 2025 designation, and the product website is no longer available, suggesting the product may be retired or replaced. No other vendors or product variants are listed in the CNA data.

Risk and Exploitability

The risk is rooted in the ability of an external attacker to override normal authorization controls by altering the ID parameter. The attack can be launched remotely with no local access required. The CVSS score of 5.3 signals moderate risk, while the absence of an EPSS score means there is currently no quantified likelihood of exploitation. Because the vulnerability has been publicly disclosed, any attacker with knowledge of the API endpoint could attempt the bypass. The fact that the product is either retired or no longer maintained increases the potential for this flaw to remain unpatched for an extended period, heightening the long‑term exposure.

Generated by OpenCVE AI on October 4, 2026 at 02:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check if a vendor patch or newer version of CoinEx Crypto 2025 is available and apply it.
  • If no patch exists, enforce ownership validation by verifying that the ID parameter belongs to the authenticated user before returning profile data.
  • Implement role‑based access control and disable the ability for unauthenticated requests to reach the "/customer/" endpoint.

Generated by OpenCVE AI on October 4, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 04 Oct 2026 01:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Omega Solution CoinEx Crypto 2025. This affects an unknown function of the file /customer/ of the component Customer Profile API. Executing a manipulation of the argument ID can lead to authorization bypass. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The product web site does not exist anymore. Maybe the product got retired and/or replaced. The vendor was contacted early about this disclosure but did not respond in any way.
Title Omega Solution CoinEx Crypto Customer Profile API customer authorization
First Time appeared Omega Solution
Omega Solution coinex Crypto
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:omega_solution:coinex_crypto:*:*:*:*:*:*:*:*
Vendors & Products Omega Solution
Omega Solution coinex Crypto
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Omega Solution Coinex Crypto
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-04T00:45:15.381Z

Reserved: 2026-10-03T09:42:53.117Z

Link: CVE-2026-105096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T02:16:28.740

Modified: 2026-10-04T02:16:28.740

Link: CVE-2026-105096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T02:30:06Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key